Fallos del tipo CWE-121

3840 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2024-30293HIGHAdobe Animate 2024 AI File parsing Stack base buffer overflow Remote Code execution VulnerabilityEPSS 0.4%CVE-2022-34667MEDIUMNVIDIA CUDA Toolkit SDK contains a stack-based buffer overflow vulnerability in cuobjdump, where an unprivileged remote attacker could exploEPSS 0.4%CVE-2024-34944HIGHTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhEPSS 0.4%CVE-2025-60342HIGHTenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. This vulnerability aEPSS 0.4%CVE-2025-60661MEDIUMTenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function.EPSS 0.4%CVE-2023-26337HIGHZDI-CAN-20285: Adobe Dimension USDA File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-71407MEDIUMA Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attEPSS 0.4%CVE-2024-35276MEDIUMA stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer EPSS 0.4%CVE-2026-42919HIGHF5 BIG-IP Appliance Mode VulnerabilityEPSS 0.4%CVE-2025-51082MEDIUMTenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/fast_setting_wifi_set. The manipulation of the argument `timeZEPSS 0.4%CVE-2025-36097HIGHIBM WebSphere Application Server denial of serviceEPSS 0.4%CVE-2025-60566HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetMACFilter.EPSS 0.4%CVE-2025-59365MEDIUMA stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigger this vulnerabilityEPSS 0.4%CVE-2022-26873HIGHThe stack buffer overflow vulnerability in PlatformInitAdvancedPreMem leads to arbitrary code execution during PEI phase.EPSS 0.4%CVE-2026-40950HIGHBuffer overflow in the Secure Access server prior to 14.50EPSS 0.4%CVE-2024-23126HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.4%CVE-2024-35579HIGHTenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv.EPSS 0.4%CVE-2024-30636MEDIUMTenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the PPPOEPassword parameter in the formQuickIndex function.EPSS 0.4%CVE-2025-50260HIGHTenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetFirewallCfg function via the firewallEn parameter.EPSS 0.4%CVE-2026-49420HIGHBuffer overflow in libalias RTSP handlerEPSS 0.4%